Skip to main content
Category: GRC Frameworks

Principled Performance

Also known as: Principled Performance®
Simply put

Principled Performance is a concept developed by OCEG that describes an organization's ability to reliably achieve its objectives while addressing uncertainty and acting with integrity. It ties together how an organization sets and meets its goals, manages the unknowns that could affect them, and conducts itself ethically and in line with its obligations. It is often used as the guiding aim of an organization's governance, risk, and compliance (GRC) efforts.

Formal definition

Principled Performance® is an OCEG-originated concept defining the aim of integrated governance, risk, and compliance (GRC) capabilities as the reliable achievement of objectives, the addressing of uncertainty, and acting with integrity. It commonly encompasses the clear articulation of an enterprise's financial and non-financial objectives and the alignment of governance structures, risk management, and compliance activities to those objectives. As a conceptual framing rather than a prescriptive standard, it does not itself specify particular controls, metrics, or implementation methods; those are typically drawn from associated GRC capability models and an organization's own business context.

Why it matters

Principled Performance offers organizations a unifying aim for governance, risk, and compliance (GRC) activities that might otherwise operate in isolation. In many organizations, governance structures, risk management, and compliance functions evolve separately, producing duplication, gaps, and conflicting priorities. By framing the goal as the reliable achievement of objectives while addressing uncertainty and acting with integrity, the concept encourages these disciplines to align around shared enterprise objectives rather than pursuing narrower functional agendas.

The framing also reflects a recognition that performance and integrity are not competing concerns. Reliably meeting financial and non-financial objectives depends on managing the uncertainties that could derail them and on conducting the enterprise ethically and in line with its obligations. Positioned as the guiding aim of GRC efforts, Principled Performance can help leadership articulate why investment in governance, risk, and compliance capabilities supports, rather than merely constrains, the pursuit of objectives.

Because it is a conceptual framing rather than a prescriptive standard, Principled Performance does not by itself dictate specific controls, metrics, or methods. Organizations typically draw those from associated GRC capability models and from their own business context. Its value lies in orienting effort toward a common outcome; the specifics of implementation remain the responsibility of each organization.

Who it's relevant to

Governance professionals and boards
Those responsible for setting direction and overseeing the organization may use Principled Performance as a way to articulate the intended outcome of governance, risk, and compliance investment, linking objectives, uncertainty, and integrity into a single guiding aim rather than treating them as separate concerns.
Risk managers
Professionals managing uncertainty against objectives may find the framing useful for positioning risk management as a contributor to reliably achieving objectives, rather than as a standalone control function. The concept does not, however, prescribe specific risk assessment or treatment methods.
Compliance officers
Those focused on adherence to obligations and acting with integrity may draw on Principled Performance to connect compliance activity to broader enterprise objectives. The concept frames integrity as integral to performance rather than a separate compliance burden.
GRC and integration leaders
Professionals working to align governance, risk, and compliance capabilities across an organization may use the concept as a shared aim to reduce duplication and conflicting priorities, drawing on associated GRC capability models and their own business context to determine specific implementation.

Inside Principled Performance

Objective-Centric Orientation
Principled Performance frames governance, risk, and compliance activities around the reliable achievement of organizational objectives, rather than treating risk or compliance as ends in themselves. The concept positions the purposeful pursuit of objectives while addressing uncertainty and acting with integrity as its organizing aim.
Integration of Governance, Risk, and Compliance
The concept promotes coordination across the three pillars so that governance structures, risk management processes, and compliance activities work in an aligned rather than siloed manner. It emphasizes shared information and consistent direction, while the distinct purpose of each pillar is retained.
Addressing Uncertainty
Principled Performance incorporates the identification, assessment, and treatment of uncertainty that could affect objectives, connecting risk considerations to the pursuit of desired outcomes rather than treating them separately.
Acting with Integrity
The concept includes adherence to applicable external requirements and internal policies, together with ethical conduct, as a condition of how objectives are pursued, linking compliance and values-based behavior to performance.
Association with the OCEG Framework
Principled Performance is a term commonly associated with OCEG (the organization that publishes GRC capability guidance) and is used to describe an integrated, capability-oriented approach to GRC. Specific model details, versions, and publication particulars are not asserted here and may vary.

Common questions

Answers to the questions practitioners most commonly ask about Principled Performance.

Is Principled Performance just another name for compliance?
No. Principled Performance is a broader capability than compliance alone. Compliance concerns adherence to external laws, regulations, and internal policies, whereas Principled Performance describes an integrated approach that aligns governance, performance objectives, risk, and compliance so an organization can reliably achieve objectives while addressing uncertainty and acting with integrity. Compliance is one component within this wider orientation rather than a synonym for it.
Does adopting Principled Performance guarantee that an organization will meet its objectives?
No. The concept describes an aspiration and an integrated way of working, not a guarantee of outcomes. It aims to improve an organization's ability to reliably achieve objectives, address uncertainty, and act with integrity, but no framework or approach can eliminate residual risk or ensure success. Its value lies in aligning governance, risk, and compliance activities toward objectives, not in assuring results.
How can an organization begin integrating governance, risk, and compliance under a Principled Performance approach?
Organizations commonly start by clarifying objectives and the decision rights, roles, and structures that direct the organization, then mapping how risk management and compliance activities support those objectives. The aim is typically to reduce siloed or duplicative efforts across functions. The specific sequencing and structure vary by jurisdiction, industry, and organization size, and this entry does not prescribe implementation specifics or tooling.
How does Principled Performance relate to established frameworks and models?
Principled Performance is an orientation that can be pursued alongside recognized frameworks rather than a substitute for them. Organizations may draw on governance structures, enterprise risk management frameworks, compliance management approaches, and assurance models to operationalize it. The choice and combination of frameworks depend on the organization's context, and this entry does not attribute the concept to any particular issuing body's mandatory requirement.
How is progress toward Principled Performance typically monitored?
Monitoring commonly involves assessing whether governance, risk, and compliance activities are aligned to objectives and whether information flows support informed decision-making. Management activities that direct and monitor performance should be distinguished from independent assurance activities that evaluate their effectiveness; keeping that separation preserves the objectivity of assurance functions. Specific metrics vary by organization and are outside the scope of this entry.
Who within an organization is responsible for advancing Principled Performance?
Responsibility is generally shared across those who set direction and those who manage and assure. In many organizations this spans governing bodies and senior management who establish objectives and oversight, operational management who own and treat risks, specialist risk and compliance functions, and independent assurance providers such as internal audit. The precise allocation of roles depends on the organization's structure and applicable governance expectations.

Common misconceptions

Principled Performance is simply another name for compliance or for a compliance program.
The concept is broader than compliance. Compliance concerns adherence to external laws, regulations, and internal policies, whereas Principled Performance frames the integrated use of governance, risk management, and compliance in service of achieving objectives with integrity. Compliance is one element within this broader orientation, not the whole of it.
Adopting Principled Performance guarantees that an organization will achieve its objectives or eliminate risk.
The concept is oriented toward the reliable pursuit of objectives while addressing uncertainty, but it does not guarantee outcomes or remove risk. Uncertainty and residual exposure typically remain, and the concept describes an approach and orientation rather than an assurance of results.
Principled Performance means merging governance, risk, and compliance into a single undifferentiated function.
The concept emphasizes integration and coordination across the pillars, not the collapse of their distinct purposes. Governance concerns direction and decision rights, risk management concerns treating uncertainty against objectives, and compliance concerns adherence to requirements; these remain distinguishable even when aligned.

Best practices

Anchor governance, risk, and compliance activities to clearly stated organizational objectives so that these activities are evaluated by their contribution to reliable objective achievement rather than treated as isolated exercises.
Establish coordination mechanisms that align governance direction, risk management, and compliance activities while preserving the distinct purpose and, where relevant, the independence of each function.
Integrate the identification, assessment, and treatment of uncertainty into planning and decision-making tied to objectives, rather than addressing risk separately from performance discussions.
Embed integrity and adherence to applicable external requirements and internal policies into how objectives are pursued, not only as a downstream check after decisions are made.
Confirm terminology and any specific framework details against current OCEG source materials before applying them, as model specifics and publication particulars may vary and should not be assumed.
Set realistic expectations with stakeholders that this orientation supports, but does not guarantee, objective achievement, acknowledging that residual uncertainty typically remains.
Application Security Isn’t Optional Anymore.